Skip to main content

Environment Variables

AISIX AI Gateway uses environment variables to select startup configuration files, override startup configuration fields, and provide deployment-specific values such as AISIX gateway certificate material.

Most runtime gateway resources are not configured directly through environment variables. For an open-source AISIX gateway, declare models, caller API keys, provider keys, guardrails, cache policies, and observability exporters in a resources.yaml file. The file supports environment interpolation for values such as ${OPENAI_API_KEY}.

For an AISIX gateway connected to AISIX Cloud, the control plane supplies these resources.

Reserved Environment Variables

AISIX reserves the following environment variables:

VariableDescription
AISIX_CONFIGConfig file path used by the AISIX binary. Equivalent to passing --config.
AISIX_CONFIG_PATHConfig file path used by the official container entrypoint. Defaults to /etc/aisix/config.yaml.
RUST_LOGProcess logging directive. When unset, AISIX uses observability.log_level.
AISIX_DP_BUDGET_STALE_MAX_SECONDSMaximum number of seconds a gateway connected to AISIX Cloud can reuse a stale budget decision after the normal cache TTL. Defaults to 600.

To use these variables, assign values before starting AISIX.

Use AISIX_CONFIG when you run the binary directly:

export AISIX_CONFIG="/etc/aisix/config.yaml"
aisix

Use AISIX_CONFIG_PATH when you use the official container entrypoint:

docker run \
-v "$(pwd)/config.prod.yaml:/etc/aisix/config.prod.yaml:ro" \
-e AISIX_CONFIG_PATH="/etc/aisix/config.prod.yaml" \
ghcr.io/api7/aisix:latest

The container entrypoint clears AISIX_CONFIG_PATH before starting the binary because it is an entrypoint variable, not a startup config field.

Startup Configuration Overrides

After AISIX loads the config file, it applies environment-variable overrides with the AISIX_ prefix. Use a single underscore after the prefix and double underscores between nested fields.

The following example overrides the proxy listener address:

export AISIX_PROXY__ADDR="0.0.0.0:3000"

Common override variables include:

VariableOverrides
AISIX_PROXY__ADDRproxy.addr
AISIX_PROXY__THREAD_PER_COREproxy.thread_per_core
AISIX_PROXY__WORKERSproxy.workers
AISIX_ETCD__ENDPOINTSetcd.endpoints
AISIX_ETCD__PREFIXetcd.prefix
AISIX_OBSERVABILITY__LOG_LEVELobservability.log_level
AISIX_CACHE__REDIS__MODEcache.redis.mode
AISIX_CACHE__REDIS__URLcache.redis.url
AISIX_CACHE__REDIS__MASTER_NAMEcache.redis.master_name
AISIX_CACHE__REDIS__USERNAMEcache.redis.username
AISIX_CACHE__REDIS__PASSWORDcache.redis.password
AISIX_CACHE__REDIS__DATABASEcache.redis.database
AISIX_RATELIMIT__BACKENDratelimit.backend
AISIX_RATELIMIT__REDIS__MODEratelimit.redis.mode
AISIX_RATELIMIT__REDIS__URLratelimit.redis.url
AISIX_RATELIMIT__REDIS__MASTER_NAMEratelimit.redis.master_name
AISIX_RATELIMIT__REDIS__USERNAMEratelimit.redis.username
AISIX_RATELIMIT__REDIS__PASSWORDratelimit.redis.password
AISIX_RATELIMIT__REDIS__DATABASEratelimit.redis.database
AISIX_RATELIMIT__CONCURRENCY_TTL_SECSratelimit.concurrency_ttl_secs
AISIX_BEDROCK_ENDPOINT_URLTop-level bedrock_endpoint_url.

etcd.endpoints accepts a comma-separated list in an environment variable.

For Redis Cluster and Sentinel node lists, configure cache.redis.nodes, cache.redis.sentinels, ratelimit.redis.nodes, or ratelimit.redis.sentinels in the startup configuration file.

For configuration file fields, see the Startup Configuration Reference.

AISIX Cloud Connection Variables

AISIX gateways use the same AISIX_ override mechanism for managed.* startup settings.

VariableDescription
AISIX_MANAGED__ENABLEDConnects the gateway to AISIX Cloud when set to true.
AISIX_MANAGED__CP_BASE_URLAISIX Cloud control-plane origin used for heartbeat, telemetry, certificate rotation, and budget checks.
AISIX_MANAGED__CP_ETCD_ENDPOINTControl-plane etcd endpoint used by the gateway at startup.
AISIX_MANAGED__CP_CA_CERT_FILEOptional CA bundle file used to trust control-plane and etcd TLS connections.
AISIX_MANAGED__CP_CERT_PEMInline client certificate PEM used for mTLS with the AISIX Cloud control plane.
AISIX_MANAGED__CP_KEY_PEMInline private key PEM paired with the client certificate.
AISIX_MANAGED__CP_CA_PEMInline CA certificate PEM used as the trust anchor.
AISIX_MANAGED__CP_CERT_FILEFile path for the client certificate PEM.
AISIX_MANAGED__CP_KEY_FILEFile path for the private key PEM.
AISIX_MANAGED__CP_CA_FILEFile path for the CA certificate PEM.
AISIX_MANAGED__MTLS_DIRDirectory where the gateway persists the materialized mTLS bundle.
AISIX_MANAGED__DP_ID_FILEFile where the gateway persists its AISIX gateway ID.
AISIX_MANAGED__SNAPSHOT_CACHE_PATHFile path for the on-disk snapshot cache used during control-plane outages.
AISIX_MANAGED__HEARTBEAT_INTERVAL_SECSAISIX gateway heartbeat interval in seconds. Defaults to 15; values are clamped between 5 and 300.

Use either the inline PEM variables or the file-path variables for the certificate, key, and CA bundle. Do not mix inline and file variants for the same bundle.

For AISIX Cloud setup, see Connect an AISIX Gateway.